Krebs on Security

February 22, 2016

The Lowdown on the Apple-FBI Showdown

This post was originally published on this siteMany readers have asked for a primer summarizing the privacy and security issues at stake in the the dispute between Apple and the U.S. Justice Department, which last week convinced a judge in California to order Apple to unlock an iPhone used by one of assailants in the recent San Bernardino massacres. I don’t have much original reporting to contribute on this important debate, but I’m visiting it here because it’s a complex topic that deserves the broadest possible public scrutiny. Image: Elin Korneliussen (@elincello) A federal magistrate in California approved an order (PDF) granting the […]
March 6, 2016

Seagate Phish Exposes All Employee W-2’s

This post was originally published on this site Email scam artists last week tricked an employee at data storage giant Seagate Technology into giving away W-2 tax documents on all current and past employees, KrebsOnSecurity has learned. W-2 forms contain employee Social Security numbers, salaries and other personal data, and are highly prized by thieves involved in filing phony tax refund requests with the Internal Revenue Service (IRS) and the states. Seagate headquarters in Cupertino, Calif. Image: Wikipedia According to Seagate, the scam struck on March 1, about a week after KrebsOnSecurity warned readers to be on the lookout for email […]
March 7, 2016

IRS Suspends Insecure ‘Get IP PIN’ Feature

This post was originally published on this site Citing ongoing security concerns, the Internal Revenue Service (IRS) has suspended a service offered via its Web site that allowed taxpayers to retrieve so-called IP Protection PINs (IP PINs), codes that the IRS has mailed to some 2.7 million taxpayers to help prevent those individuals from becoming victims of tax refund fraud two years in a row. The move comes just days after KrebsOnSecurity first exposed how ID thieves were abusing the service to revisit tax refund on innocent taxpayers two years running. Last week, this blog told the story of Becky Wittrock, […]
March 8, 2016

Adobe, Microsoft Push Critical Updates

This post was originally published on this site08Mar 16 Adobe, Microsoft Push Critical Updates Microsoft today pushed out 13 security updates to fix at least 39 separate vulnerabilities in its various Windows operating systems and software. Five of the updates fix flaws that allow hackers or malware to break into vulnerable systems without any help from the user, save for perhaps visiting a hacked Web site. The bulk of the security holes plugged in this month’s Patch Tuesday reside in either Internet Explorer or in Microsoft’s flagship browser — Edge. As security firm Shavlik notes, Microsoft’s claim that Edge is […]